vendor:
IBM 1754 GCM
by:
Unknown
8.5
CVSS
HIGH
Command execution
78
CWE
Product Name: IBM 1754 GCM
Affected Version From: GCM16 (v.1.18.0.22011) and older versions
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2013-0526
CPE: a:ibm:1754_gcm
Platforms Tested:
2013
IBM 1754 GCM Command Execution Vulnerability
GCM16 (v.1.18.0.22011) and older versions of this KVM switch contain a flaw that allows a remote authenticated user to execute unauthorized commands as root. This flaw exists because webapp variables are not sanitized. In this case, parameters $count and $size from ping.php allow to create a special crafted URL to inject text to an exec() so it can be arbitrarily used to execute any command on the KVM embedded linux.
Mitigation:
Upgrade to a version newer than GCM16 (v.1.18.0.22011) that addresses this vulnerability. Sanitize webapp variables to prevent command injection.